Cross-site scripting in RubyGems - CVE-2019-8322
Published: August 13, 2019
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when displaying contents of the API response directly to stdout. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power
Opensuse
Fedora
EMC Integrated Data Protection Appliance
ruby (Red Hat package)
ruby (Alpine package)
rh-ruby24-ruby (Red Hat package)
rh-ruby25-ruby (Red Hat package)
ruby
Dell EMC Data Protection Search
How to mitigate CVE-2019-8322
EMC Integrated Data Protection Appliance - update to 2.7.1
ruby (Red Hat package) - update to 2.0.0.648-37.el7_4
ruby (Alpine package) - update to 2.4.6-r0
Dell EMC Data Protection Search - update to 19.6.0
rh-ruby24-ruby (Red Hat package) - addressed in versions 2.4.6-92.el6, 2.4.6-92.el7
rh-ruby25-ruby (Red Hat package) - update to 2.5.5-7.el7
ruby - addressed in versions 2.5.5-101.fc29, 2.5.5-108.fc28
External References
Related Security Bulletins
- Amazon Linux AMI update for ruby20, ruby21, ruby24
- Multiple vulnerabilities in RubyGems
- OpenSUSE Linux update for ruby-bundled-gems-rpmhelper, ruby2.5
- Red Hat update for ruby
- Red Hat Enterprise Linux 8 update for the ruby:2.5 module
- Red Hat Enterprise Linux 7 update for ruby
- Cross-site scripting in ruby (Alpine package)
- Multiple vulnerabilities in Dell EMC Integrated Data Protection Appliance
- Multiple vulnerabilities in Dell EMC Data Protection Search
- Red Hat Software Collections update for rh-ruby25-ruby
- Red Hat Software Collections update for rh-ruby24-ruby
- Fedora 29 update for ruby
- Fedora 28 update for ruby